Personal-management-system
Personal-management-system Personal Management System: vulnerabilidades y CVE
Personal-management-system Personal Management System tiene 11 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40526 | Alta (7.1) | 0.80% | — | 27 ago 2026 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint.… |
| CVE-2024-53569 | Media (5.4) | 0.22% | — | 22 abr 2025 | A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a… |
| CVE-2024-53568 | Media (5.4) | 0.22% | — | 22 abr 2025 | A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted… |
| CVE-2025-28355 | Media (4.7) | 0.21% | — | 18 abr 2025 | Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value… |
| CVE-2025-29456 | Media (6.5) | 0.38% | — | 17 abr 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function. |
| CVE-2025-29453 | Media (6.5) | 0.38% | — | 17 abr 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component. |
| CVE-2025-29455 | Media (6.5) | 0.38% | — | 17 abr 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function. |
| CVE-2025-29454 | Media (6.5) | 0.38% | — | 17 abr 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function. |
| CVE-2024-29319 | Crítica (9.8) | 0.39% | — | 5 jul 2024 | Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls. |
| CVE-2024-29318 | Media (5.4) | 0.33% | — | 5 jul 2024 | Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code. |
| CVE-2023-43838 | Alta (7.8) | 0.60% | — | 4 oct 2023 | An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.